S3Proxy Filesystem Backends Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in S3Proxy's filesystem and filesystem-nio2 storage backends, allowing authenticated users to unintentionally access local files. This issue affects S3Proxy versions prior to 2.6.0 and has been patched in version 2.6.0.

Impact

Exploitation of this vulnerability could lead to unauthorized access to local files on the server, potentially exposing sensitive information to authenticated users.

Reproduction

The vulnerability can be reproduced by uploading a file with a name that includes path traversal sequences, such as '../evil.txt', to a container in the affected storage backend. The file will be accessible through the S3 API, exposing local files to authenticated users.

Remediation

Users are advised to upgrade to S3Proxy version 2.6.0 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.3
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.